191 characters · 1 words · 191 bytes (UTF-8)
Output will appear here
Click in the output to select all text
191 characters · 1 words · 191 bytes (UTF-8)
Output will appear here
Click in the output to select all text
Construct and sign a JSON Web Token using HS256 algorithm and a secret key.
Generate HMAC signatures using SHA-256, SHA-512, SHA-1, or MD5 with a secret key.
URL-safe Base64 encoding and decoding without padding or special URL characters.
Decode and inspect PEM-encoded X.509 certificates (subject, issuer, validity, SANs).
This JWT decoder breaks a JSON Web Token into its header, payload, and signature components and displays the decoded claims in readable JSON, instantly in your browser. JWTs are the standard bearer-token format for stateless authentication and API authorization, encoding claims like the subject, issuer, expiration, and custom application data inside a Base64URL-encoded, dot-separated string — decoding one is essential when debugging why a login is failing, checking token expiration, or inspecting what data an API is actually embedding in its access tokens. Backend and frontend developers debugging auth flows, API integrators inspecting third-party tokens, and security reviewers auditing what claims a token exposes will all find this decoder immediately useful. Because JWTs frequently carry sensitive claims — user IDs, roles, sometimes more than they should — every part of the decoding happens locally in your browser via JavaScript; your token is never transmitted to, logged by, or stored on any server. There's no signup and decoding is instant as you paste. Note this tool decodes and displays claims but does not verify the cryptographic signature; if you need to construct and sign a new token, use this platform's JWT generator. Scroll down to decode your JWT now.
It's safe with this tool specifically because decoding happens entirely in your browser and the token is never sent to a server — but be cautious with any tool where you can't verify that, since JWTs often contain sensitive claims.
No, decoding only reveals the header and payload content; verifying the signature requires the correct secret key or public key and confirms the token hasn't been tampered with.
Yes, standard JWTs are only Base64URL-encoded, not encrypted, so anyone with the token can decode and read its claims — never put secret data directly inside a JWT payload.
The 'exp' (expiration) claim is a Unix timestamp indicating when the token becomes invalid; servers should reject any JWT presented after this time.
The header specifies metadata like the signing algorithm and token type, while the payload contains the actual claims — the data about the user or session the token represents.
This usually means the token was truncated, modified, or isn't a valid JWT at all — double-check you copied the complete three-part, dot-separated string.
Yes, decoding shows the 'exp' claim converted to a human-readable date, so you can quickly see whether a token has already expired.